← IdenTrust Services, LLC cases
Bugzilla #1933353 Self Reported Incident

IdenTrust: Incorrect response for OCSP validation

RESOLVED FIXED IdenTrust Services, LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

On November 23, 2024, IdenTrust discovered an issue where a limited number of TLS certificates returned an unauthorized OCSP response during a maintenance window. The CA quickly remediated the issue and provided a complete incident report by December 6, 2024. The root cause was identified as a bug in the REST API that affected internal OCSP responders due to a database time zone mismatch. IdenTrust implemented several corrective actions, including fixing the API, enhancing logging, and improving alert systems. All action items were completed, and the incident was resolved by March 10, 2025.

Model: gpt-4o-mini Generated: 2026-06-13 21:31 UTC Revised: 2026-06-16 19:28 UTC Confidence: 0.90 11 comments
Chronology
  1. IdenTrust discovered unauthorized OCSP responses for TLS certificates.
  2. IdenTrust deployed logging capabilities for OCSP responders.
Thread Activity
  1. IdenTrust Services, LLC — IdenTrust reported an issue with unauthorized OCSP responses discovered during maintenance.
  2. IdenTrust Services, LLC — IdenTrust provided a complete incident report detailing the unauthorized OCSP response issue.
  3. IdenTrust Services, LLC — IdenTrust updated on improvements to the alert system.
  4. IdenTrust Services, LLC — IdenTrust confirmed deployment of logging capabilities for OCSP responders.
  5. Mozilla representative — Mozilla queued the bug for closure.
Participants
IdenTrust Services, LLC Mozilla representative
External References
Similar Local Cases
#1910195 RESOLVED Certificate Misissuance Self Reported Incident Opened 2024-07-26 · Closed 2024-09-06 · 97% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1930029 RESOLVED Self Reported Incident Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 97% similar
IdenTrust: Approval of TLS certificate renewal without domain validation
#1794047 RESOLVED Revocation Issue Self Reported Incident Opened 2022-10-06 · Closed 2023-02-22 · 96% similar
IdenTrust: Missing Revocation Reasons in CRL
#1853783 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2023-09-18 · Closed 2025-03-20 · 95% similar
IdenTrust: S/MIME certificates issued in violation of New S/MIME Baseline Requirements v1.0
#1598807 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2019-11-23 · Closed 2023-02-22 · 95% similar
IdenTrust: Undisclosed Unrevoked ICAs
#2014609 RESOLVED Self Reported Incident Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 91% similar
IdenTrust: Cross-signed root certificate mis-issuance
#1991558 RESOLVED Self Reported Incident Opened 2025-09-29 · Closed 2026-01-15 · 90% similar
IdenTrust: TLS self audit testing below 3%
#2014590 RESOLVED Self Reported Incident Incident Opened 2026-02-04 · Closed 2026-04-23 · 90% similar
IdenTrust: Unauthorized OCSP responses for cross-signed roots

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action